CVE-2019-5433

A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks. This vulnerability was addressed in version 4.2.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:44

Type Values Removed Values Added
References () https://hackerone.com/reports/390663 - Exploit, Third Party Advisory () https://hackerone.com/reports/390663 - Exploit, Third Party Advisory
References () https://www.revive-adserver.com/security/revive-sa-2019-001/ - Patch, Vendor Advisory () https://www.revive-adserver.com/security/revive-sa-2019-001/ - Patch, Vendor Advisory

Information

Published : 2019-05-06 17:29

Updated : 2024-11-21 04:44


NVD link : CVE-2019-5433

Mitre link : CVE-2019-5433

CVE.ORG link : CVE-2019-5433


JSON object : View

Products Affected

revive-adserver

  • revive_adserver
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')